A Non-Technical XACML Target Editor for Dynamic Access Control Systems

被引:0
|
作者
Stepien, Bernard [1 ]
Felty, Amy [1 ]
Matwin, Stan [2 ]
机构
[1] Univ Ottawa, Sch Elect Engn & Comp Sci, Ottawa, ON, Canada
[2] Dalhousie Univ, Polish Acad Sci, Fac Comp Sci, Canada Inst Comp Sci, Halifax, NS, Canada
关键词
component; Access control; XACML; policy administration point; ABAC; RBAC;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
XACML is a powerful and flexible access control (AC) policy language. It is an OASIS standard that is now widely used in a variety of applications, particularly those that require interoperability between AC systems. The language definition includes a precise grammar, syntax, and semantics, and it is both expressive and verbose. This combination of expressive power and verbosity can lead to difficulty in understanding the language's syntax and semantics for both technical and nontechnical users alike. As a result, reducing the difficulty of editing XACML policies has become an intense area of research. In our own work in this area, we previously showed how to render complex XACML conditions using a non-technical display notation and showed that it is easy to use this notation with interactive plain text editors that do not require any technical coding. Although XACML conditions are expressive and flexible, XACML targets are actually the most commonly used XACML language construct. They have an additional level of complexity, especially in version 3.0, due to the fact that the form and kinds of XACML constructs allowed in targets is much more limited. This paper extends our previous work, showing how the same powerful and flexible interactive editing principles can be applied to targets in order to allow users to use natural logic rather than implementation logic. We extend these principles and fully integrate them into our editing tool, easyXACML. This tool is usable by users with no technical knowledge of XACML, thus making XACML totally transparent to the user, while still retaining all of its functionalities and semantics. Our tool thus allows users to focus on policy logic rather than on details of syntax. As a result, the risk of errors in policies is greatly reduced.
引用
收藏
页码:150 / 157
页数:8
相关论文
共 50 条
  • [1] A Non-technical User-Oriented Display Notation for XACML Conditions
    Stepien, Bernard
    Felty, Amy
    Matwin, Stan
    E-TECHNOLOGIES-INNOVATION IN AN OPEN WORLD, 2009, 26 : 53 - +
  • [2] Advantages of a Non-Technical XACML Notation in Role-Based Models
    Stepien, Bernard
    Matwin, Stan
    Felty, Amy
    2011 NINTH ANNUAL INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, 2011, : 193 - 200
  • [3] NON-TECHNICAL SIDE OF SYSTEMS
    CANAVAN, EM
    JOURNAL OF SYSTEMS MANAGEMENT, 1979, 30 (09): : 16 - 17
  • [4] Non-technical threat to computing systems
    Science Applications Int Corp
    Comput Syst, 1 (3-14):
  • [5] The non-technical threat to computing systems
    Winkler, IS
    COMPUTING SYSTEMS, 1996, 9 (01): : 3 - 14
  • [6] Evaluating a Concept Map Editor with non-technical students
    Rueda, Urko
    Arruarte, Ana
    Elorriaga, Jon A.
    Herran, Elena
    8TH IEEE INTERNATIONAL CONFERENCE ON ADVANCED LEARNING TECHNOLOGIES, PROCEEDINGS, 2008, : 405 - 407
  • [7] Integrating technical and non-technical issues in control education
    Brandt, D
    Imamichi, C
    McGregor, H
    Moses, I
    vanderVorst, R
    CONTROL ENGINEERING PRACTICE, 1996, 4 (05) : 655 - 662
  • [8] Min-Max Control Over Transfer Characteristics in Models of Technical and Non-Technical Systems
    Kovacevic, Darko
    Zujic, Mijo
    Kovacevic, Asja
    2015 17TH UKSIM-AMSS INTERNATIONAL CONFERENCE ON COMPUTER MODELLING AND SIMULATION (UKSIM), 2015, : 588 - 593
  • [9] Managing the policies of non-technical users in a dynamic world
    Owen, T
    Wakeman, I
    Keller, B
    Weeds, J
    Weir, D
    SIXTH IEEE INTERNATIONAL WORKSHOP ON POLICIES FOR DISTRIBUTED SYSTEMS AND NETWORKS, PROCEEDINGS, 2005, : 251 - 254
  • [10] Formal representation of conflict zones in XACML access control systems
    Yahiaoui, Mohamed
    Zinedine, Ahmed
    Harti, Mostafa
    2012 COLLOQUIUM ON INFORMATION SCIENCE AND TECHNOLOGY (CIST'12), 2012, : 123 - 129